Improper Restriction of Excessive Authentication Attempts in OpenEMR - #VU149483
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive patient information and perform patient-facing actions.
The vulnerability exists due to improper restriction of excessive authentication attempts in the PIN-validation branch of OneTimeAuth.php::processOnetime() when validating login PIN values for an invoice token. A remote attacker can submit repeated PIN guesses with a captured invoice token to disclose sensitive patient information and perform patient-facing actions.
Invoice tokens may remain valid for up to 14 days.